Oval Definition:oval:org.opensuse.security:def:59787
Revision Date:2021-08-25Version:1
Title:Security update for unrar (Moderate)
Description:

This update for unrar to version 5.6.1 fixes several issues.

These security issues were fixed:

- CVE-2017-12938: Prevent remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a symlink to the .. directory, and a regular file (bsc#1054038). - CVE-2017-12940: Prevent out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function (bsc#1054038). - CVE-2017-12941: Prevent an out-of-bounds read in the Unpack::Unpack20 function (bsc#1054038). - CVE-2017-12942: Prevent a buffer overflow in the Unpack::LongLZ function (bsc#1054038). - CVE-2017-20006: Fixed heap-based buffer overflow in Unpack:CopyString (bsc#1187974).

These non-security issues were fixed:

- Added extraction support for .LZ archives created by Lzip compressor - Enable unpacking of files in ZIP archives compressed with XZ algorithm and encrypted with AES - Added support for PAX extended headers inside of TAR archive - If RAR recovery volumes (.rev files) are present in the same folder as usual RAR volumes, archive test command verifies .rev contents after completing testing .rar files - By default unrar skips symbolic links with absolute paths in link target when extracting unless -ola command line switch is specified - Added support for AES-NI CPU instructions - Support for a new RAR 5.0 archiving format - Wildcard exclusion mask for folders - Prevent conditional jumps depending on uninitialised values (bsc#1046882)
Family:unixClass:patch
Status:Reference(s):1027353
1028842
1046882
1049825
1054038
1056127
1056128
1056129
1056131
1056132
1056136
1062063
1066644
1070046
1071459
1071460
1081164
1088004
1088009
1097158
1097748
1101644
1101645
1101651
1101656
1102775
1103511
1104668
1105019
1109893
1110542
1111122
1111319
1112142
1112143
1112144
1112146
1112147
1112152
1112153
1112911
1113296
1116995
1120489
1120629
1120630
1120631
1127155
1130840
1131823
1133191
1134226
1136446
1136935
1137597
1137977
1140039
1141853
1145521
1149955
1153238
1160467
1160468
1162423
1167373
1173274
1173304
1174091
1174701
1187974
CVE-2011-0461
CVE-2011-3200
CVE-2012-6706
CVE-2013-4758
CVE-2013-6370
CVE-2013-6371
CVE-2014-3634
CVE-2014-3683
CVE-2015-9262
CVE-2016-0705
CVE-2017-1000159
CVE-2017-12938
CVE-2017-12940
CVE-2017-12941
CVE-2017-12942
CVE-2017-13728
CVE-2017-13729
CVE-2017-13730
CVE-2017-13731
CVE-2017-13732
CVE-2017-13733
CVE-2017-16548
CVE-2017-17433
CVE-2017-17434
CVE-2017-20006
CVE-2017-3732
CVE-2017-3736
CVE-2018-0732
CVE-2018-12115
CVE-2018-12539
CVE-2018-13785
CVE-2018-14647
CVE-2018-1517
CVE-2018-16435
CVE-2018-1656
CVE-2018-18065
CVE-2018-20217
CVE-2018-20532
CVE-2018-20533
CVE-2018-20534
CVE-2018-20852
CVE-2018-2938
CVE-2018-2940
CVE-2018-2952
CVE-2018-2964
CVE-2018-2973
CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3169
CVE-2018-3180
CVE-2018-3214
CVE-2018-3639
CVE-2019-11477
CVE-2019-11478
CVE-2019-11487
CVE-2019-14896
CVE-2019-14897
CVE-2019-16056
CVE-2019-16935
CVE-2019-18860
CVE-2019-20907
CVE-2019-3846
CVE-2019-9947
CVE-2020-14059
CVE-2020-14422
SUSE-SU-2018:0118-1
SUSE-SU-2018:0120-1
SUSE-SU-2018:0947-1
SUSE-SU-2018:2796-1
SUSE-SU-2018:2841-1
SUSE-SU-2020:1803-1
SUSE-SU-2020:2699-1
SUSE-SU-2021:2834-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • curl-7.59.0-lp150.1 is installed
  • OR libcurl4-7.59.0-lp150.1 is installed
  • OR libcurl4-32bit-7.59.0-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libpng16-1.6.34-lp151.3.3 is installed
  • OR libpng16-16-1.6.34-lp151.3.3 is installed
  • OR libpng16-16-32bit-1.6.34-lp151.3.3 is installed
  • OR libpng16-compat-devel-1.6.34-lp151.3.3 is installed
  • OR libpng16-compat-devel-32bit-1.6.34-lp151.3.3 is installed
  • OR libpng16-devel-1.6.34-lp151.3.3 is installed
  • OR libpng16-devel-32bit-1.6.34-lp151.3.3 is installed
  • OR libpng16-tools-1.6.34-lp151.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • java-1_8_0-ibm-1.8.0_sr5.20-30.36 is installed
  • OR java-1_8_0-ibm-alsa-1.8.0_sr5.20-30.36 is installed
  • OR java-1_8_0-ibm-devel-1.8.0_sr5.20-30.36 is installed
  • OR java-1_8_0-ibm-plugin-1.8.0_sr5.20-30.36 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • aaa_base-13.2+git20140911.61c1681-36 is installed
  • OR aaa_base-extras-13.2+git20140911.61c1681-36 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND squid-3.5.21-26.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND xrdp-0.9.0~git.1456906198.f422461-21.27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • ntp-4.2.8p15-88 is installed
  • OR ntp-doc-4.2.8p15-88 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libdcerpc-binding0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libdcerpc-binding0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libdcerpc0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libdcerpc0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libndr-krb5pac0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libndr-krb5pac0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libndr-nbt0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libndr-nbt0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libndr-standard0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libndr-standard0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libndr0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libndr0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libnetapi0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libnetapi0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-credentials0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-credentials0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-errors0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-errors0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-hostconfig0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-hostconfig0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-passdb0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-passdb0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-util0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamba-util0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamdb0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsamdb0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsmbclient0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsmbclient0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsmbconf0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsmbconf0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsmbldap0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libsmbldap0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libtevent-util0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libtevent-util0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libwbclient0-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR libwbclient0-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR samba-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR samba-client-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR samba-client-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR samba-doc-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR samba-libs-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR samba-libs-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR samba-winbind-4.6.16+git.124.aee309c5c18-3.32 is installed
  • OR samba-winbind-32bit-4.6.16+git.124.aee309c5c18-3.32 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND chrony-2.3-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND unrar-5.6.1-4.5.1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND squid-3.5.21-26.26 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND haproxy-1.6.11-11.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND nodejs6-6.14.4-11.18 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • crowbar-core-6.0+git.1569587091.3f083d63c-3.10 is installed
  • OR crowbar-core-branding-upstream-6.0+git.1569587091.3f083d63c-3.10 is installed
  • OR crowbar-ha-6.0+git.1567673476.1342c3d-3.10 is installed
  • OR crowbar-openstack-6.0+git.1569805311.a94583476-3.10 is installed
  • OR crowbar-ui-1.3.0+git.1568396400.0344a727-11 is installed
  • OR grafana-6.2.5-3.6 is installed
  • OR grafana-monasca-ui-drilldown-1.14.1~dev9-3.6 is installed
  • OR novnc-1.1.0-3.3 is installed
  • OR openstack-cinder-13.0.7~dev16-3.10 is installed
  • OR openstack-cinder-api-13.0.7~dev16-3.10 is installed
  • OR openstack-cinder-backup-13.0.7~dev16-3.10 is installed
  • OR openstack-cinder-scheduler-13.0.7~dev16-3.10 is installed
  • OR openstack-cinder-volume-13.0.7~dev16-3.10 is installed
  • OR openstack-dashboard-14.0.4~dev11-3.6 is installed
  • OR openstack-designate-7.0.1~dev22-3.10 is installed
  • OR openstack-designate-agent-7.0.1~dev22-3.10 is installed
  • OR openstack-designate-api-7.0.1~dev22-3.10 is installed
  • OR openstack-designate-central-7.0.1~dev22-3.10 is installed
  • OR openstack-designate-producer-7.0.1~dev22-3.10 is installed
  • OR openstack-designate-sink-7.0.1~dev22-3.10 is installed
  • OR openstack-designate-worker-7.0.1~dev22-3.10 is installed
  • OR openstack-glance-17.0.1~dev30-3.3 is installed
  • OR openstack-glance-api-17.0.1~dev30-3.3 is installed
  • OR openstack-heat-11.0.3~dev23-3.10 is installed
  • OR openstack-heat-api-11.0.3~dev23-3.10 is installed
  • OR openstack-heat-api-cfn-11.0.3~dev23-3.10 is installed
  • OR openstack-heat-engine-11.0.3~dev23-3.10 is installed
  • OR openstack-heat-plugin-heat_docker-11.0.3~dev23-3.10 is installed
  • OR openstack-horizon-plugin-heat-ui-1.4.1~dev4-4.6 is installed
  • OR openstack-horizon-plugin-monasca-ui-1.14.1~dev9-3.6 is installed
  • OR openstack-ironic-11.1.4~dev15-3.10 is installed
  • OR openstack-ironic-api-11.1.4~dev15-3.10 is installed
  • OR openstack-ironic-conductor-11.1.4~dev15-3.10 is installed
  • OR openstack-ironic-python-agent-3.3.3~dev5-3.10 is installed
  • OR openstack-keystone-14.1.1~dev16-3.10 is installed
  • OR openstack-manila-7.3.1~dev6-4.10 is installed
  • OR openstack-manila-api-7.3.1~dev6-4.10 is installed
  • OR openstack-manila-data-7.3.1~dev6-4.10 is installed
  • OR openstack-manila-scheduler-7.3.1~dev6-4.10 is installed
  • OR openstack-manila-share-7.3.1~dev6-4.10 is installed
  • OR openstack-neutron-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-dhcp-agent-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-gbp-5.0.1~dev472-3.10 is installed
  • OR openstack-neutron-ha-tool-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-l3-agent-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-linuxbridge-agent-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-macvtap-agent-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-metadata-agent-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-metering-agent-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-openvswitch-agent-13.0.5~dev50-3.10 is installed
  • OR openstack-neutron-server-13.0.5~dev50-3.10 is installed
  • OR openstack-nova-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-api-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-cells-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-compute-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-conductor-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-console-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-novncproxy-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-placement-api-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-scheduler-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-serialproxy-18.2.3~dev22-3.10 is installed
  • OR openstack-nova-vncproxy-18.2.3~dev22-3.10 is installed
  • OR openstack-octavia-3.1.2~dev45-3.10 is installed
  • OR openstack-octavia-amphora-agent-3.1.2~dev45-3.10 is installed
  • OR openstack-octavia-api-3.1.2~dev45-3.10 is installed
  • OR openstack-octavia-health-manager-3.1.2~dev45-3.10 is installed
  • OR openstack-octavia-housekeeping-3.1.2~dev45-3.10 is installed
  • OR openstack-octavia-worker-3.1.2~dev45-3.10 is installed
  • OR openstack-sahara-9.0.2~dev12-3.3 is installed
  • OR openstack-sahara-api-9.0.2~dev12-3.3 is installed
  • OR openstack-sahara-engine-9.0.2~dev12-3.3 is installed
  • OR openstack-tempest-19.0.0-15 is installed
  • OR openstack-tempest-test-19.0.0-15 is installed
  • OR openstack-watcher-1.12.1~dev19-4.3 is installed
  • OR openstack-watcher-doc-1.12.1~dev19-4.3 is installed
  • OR python-cinder-13.0.7~dev16-3.10 is installed
  • OR python-cinder-tempest-plugin-0.1.0-11 is installed
  • OR python-designate-7.0.1~dev22-3.10 is installed
  • OR python-glance-17.0.1~dev30-3.3 is installed
  • OR python-heat-11.0.3~dev23-3.10 is installed
  • OR python-horizon-14.0.4~dev11-3.6 is installed
  • OR python-horizon-plugin-heat-ui-1.4.1~dev4-4.6 is installed
  • OR python-horizon-plugin-monasca-ui-1.14.1~dev9-3.6 is installed
  • OR python-ironic-11.1.4~dev15-3.10 is installed
  • OR python-keystone-14.1.1~dev16-3.10 is installed
  • OR python-manila-7.3.1~dev6-4.10 is installed
  • OR python-neutron-13.0.5~dev50-3.10 is installed
  • OR python-neutron-gbp-5.0.1~dev472-3.10 is installed
  • OR python-nova-18.2.3~dev22-3.10 is installed
  • OR python-octavia-3.1.2~dev45-3.10 is installed
  • OR python-openstack_auth-14.0.4~dev11-3.6 is installed
  • OR python-sahara-9.0.2~dev12-3.3 is installed
  • OR python-tempest-19.0.0-15 is installed
  • OR python-urllib3-1.23-3.9 is installed
  • OR python-watcher-1.12.1~dev19-4.3 is installed
  • OR ruby2.1-rubygem-easy_diff-1.0.0-4.3 is installed
  • OR rubygem-easy_diff-1.0.0-4.3 is installed
  • BACK